Malware & Threats

Iranian Hackers Use New Tickler Malware for Intelligence Gathering on Critical Infrastructure

The Iran-linked state-sponsored hacker group tracked as Peach Sandstorm has started using a new backdoor in attacks aimed at the US and UAE.

Iran

An Iranian state-sponsored threat actor has been using a new custom backdoor in attacks aimed at organizations in the United States and the United Arab Emirates, according to Microsoft.

The tech giant tracks the group as Peach Sandstorm, but it’s also known as APT33, Elfin, Holmium, Magnallium, and Refined Kitten. In late 2023, Microsoft reported seeing the threat actor targeting employees at US defense industrial base organizations. 

Microsoft has observed Peach Sandstorm using a new piece of malware that it has named Tickler in intelligence gathering operations targeting satellite, communications equipment, government, and oil and gas organizations in the US and UAE. 

Tickler has been described as a custom, multi-stage backdoor that enables the attackers to download additional malware to compromised systems. The malicious payloads observed by Microsoft were capable of collecting systems information, executing commands, deleting files, and downloading/uploading files from/to a command and control (C&C) server.

The tech giant has continued to see Peach Sandstorm leveraging LinkedIn for intelligence gathering and social engineering attacks. 

The hackers have also continued launching password spray attacks, recently being seen conducting such operations against organizations in the defense, space, education, and government sectors in the US and Australia.

Advertisement. Scroll to continue reading.

The company also noted that the threat actors “leveraged Azure infrastructure hosted in fraudulent, attacker-controlled Azure subscriptions for command-and-control”.

Microsoft published its report on the same day Google Cloud’s Mandiant published a report on an Iranian counterintelligence operation, and the US government issued an advisory on how Iranian state-sponsored actors have been collaborating with ransomware groups

Microsoft, Google, Meta and the US government recently also issued reports on Iranian hackers targeting elections.

Related: How Lessons Learned From the 2016 Campaign Led US Officials to Be More Open About Iran Hack

Related: Google Disrupts Iranian Hacking Activity Targeting US Presidential Election

Related Content

Malware & Threats

The attackers impersonate at least 40 companies and disable 145 security products to deploy infostealer malware.

Artificial Intelligence

Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.

Malware & Threats

Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts.

Malware & Threats

US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C.

Artificial Intelligence

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers.

Artificial Intelligence

The Humanist AI Code of Conduct draws a line between defensive cyber research and operational attack capability.

Malware & Threats

Ads led to a ClickFix page designed to trick macOS and Windows users into installing malware.

Malware & Threats

The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version